[DEEP RESEARCH] The Container Was Not the Prize. The Token Was.
A pod compromise becomes a control-plane problem when workload identity turns execution into transitive authority. Kubernetes service-account tokens are not universal master keys, but permissive RBAC, workload federation, cloud IAM, and reachable credentials can connect one application incident to cluster and cloud impact.